[Snort-users] 2.1.3RC1 event_queue and custom ruletypes/log rules?
emf at ...367...
Tue Apr 27 21:47:01 EDT 2004
-----BEGIN PGP SIGNED MESSAGE-----
Are custom rule types not part of the new event_queue?
(which, by the way, I think I like.)
a totally contrived example:
output alert_syslog: log_auth log_alert
output log_tcpdump: alerts.log
output log_tcpdump: traffic.log
traffic ip any any -> any any
alert tcp any any -> any 23 (msg: "sample alert";)
does not produce expected behavior.. the "sample alert" packets do not
appear in traffic.log, only in alerts.log. So, I think to myself
'self.. perhaps it only works on "alert" types.' so I make "traffic"
an "alert" type (with output alert_fast: /dev/null (YUCK!)).. same
behavior. So.... help?
Principal Engineer, Information Security, ServerVault Corp.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (FreeBSD)
-----END PGP SIGNATURE-----
More information about the Snort-users